From nobody Mon Sep 28 21:03:43 2026 Received: from remote.fiveco.ch (remote.fiveco.ch [46.14.118.250]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 801AD4399D7 for ; Mon, 17 Aug 2026 13:25:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=46.14.118.250 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786973143; cv=none; b=EBpayBq6GfOHOH9kY+/7ny67ngXroT1SGdeIpkhA4ZhwA5ju6GhtwngcWmIsg51ZbqrF8ScvCp4yTAPjTiCpx83xrZgeYjkdLSjweg1bPJEqc4N+KENQK6PHCiGaSROteRe8Gi5F+5C2eTgKcJPQsDTi9VDLVPusZ5GJX9nT+2M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786973143; c=relaxed/simple; bh=2bqgYurh8iwQTQa/keWKcKZ+VVDHHq6p4qTQ51UEFgU=; h=Content-Type:From:To:CC:Subject:Date:Message-ID:In-Reply-To: References:MIME-Version; b=opTVu+FzEJtlpH/5X28layGnMcHvynaua5oHXAGb1G2vINhJBb4JLNGfjHHgFcPk+fQ/MF5UZRZL0xC+crbI12vnBZ1HHpxFlWZSmF9vUpsJz/eh7PovJ6HojwHATHVzWCvHVab2zjbQq/37UdVpOLFuFLFBDdqJqHEtcVK+AQ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=fiveco.ch; spf=pass smtp.mailfrom=fiveco.ch; dkim=pass (1024-bit key) header.d=fiveco.ch header.i=@fiveco.ch header.b=DNK7v3Zd; arc=none smtp.client-ip=46.14.118.250 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=fiveco.ch Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=fiveco.ch Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=fiveco.ch header.i=@fiveco.ch header.b="DNK7v3Zd" Received: from [192.168.16.44] (port=25366 helo=remote.fiveco.ch) by remote.fiveco.ch with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1wvxKp-000000001aq-3aZr; Mon, 17 Aug 2026 15:25:03 +0200 Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; d=fiveco.ch; s=fiveco; c=simple/simple; t=1786973103; h=from:subject:to:date:message-id; bh=2bqgYurh8iwQTQa/keWKcKZ+VVDHHq6p4qTQ51UEFgU=; b=DNK7v3Zdlxz9C1HyjCpjDt1f3D0YjnifJbTq/bii1ywqBeBMNbTct+g2j9LP2Dfi2TQDIsf5ph7 T27iCiNmoUazY+L83BCB9gZ2Ofwlx5BJtcAlI4mNGOgODD0e+4lqscyfG4+KP8mJKl5d27dBU0fSc ZtfiV48PklBusLZNnGA= Received: from fiveco-vm-vk1.fiveco.local (192.168.16.29) by FIVECO-MX01.fiveco.local (192.168.16.44) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.61; Mon, 17 Aug 2026 15:25:03 +0200 From: Valentin Kindschi To: CC: , , , , Valentin Kindschi , Subject: [PATCH v2 1/2] Bluetooth: hci_conn: only re-enable advertising after a failed peripheral connection Date: Mon, 17 Aug 2026 15:24:48 +0200 Message-ID: <20260817132449.509304-2-valentin.kindschi@fiveco.ch> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260817132449.509304-1-valentin.kindschi@fiveco.ch> References: <20260817132449.509304-1-valentin.kindschi@fiveco.ch> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-ClientProxiedBy: FIVECO-MX01.fiveco.local (192.168.16.44) To FIVECO-MX01.fiveco.local (192.168.16.44) X-Sophos-OBS: success X-SASI-Version: Antispam-Engine: 6.0.0.1, AntispamData: 2026.8.17.125719 X-SASI-RCODE: 200 X-SASI-SpamProbability: 8% X-SASI-Hits: BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, MULTIPLE_RCPTS 0.100000, NO_CTA_URI_FOUND 0.000000, NO_FUR_HEADER 0.000000, NO_URI_HTTPS 0.000000, OUTBOUND 0.000000, OUTBOUND_SOPHOS 0.000000, REFERENCES 0.000000, SENDER_NO_AUTH 0.000000, WEBMAIL_SOURCE 0.000000, WEBMAIL_XOIP 0.000000, WEBMAIL_X_IP_HDR 0.000000, __ANY_URI 0.000000, __BODY_NO_MAILTO 0.000000, __BODY_VOICEMAIL 0.000000, __BULK_NEGATE 0.000000, __CC_NAME 0.000000, __CC_NAME_DIFF_FROM_ACC 0.000000, __CC_REAL_NAMES 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FUR_RDNS_SOPHOS 0.000000, __HAS_CC_HDR 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_XOIP 0.000000, __HAS_X_MAILER 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MSGID_DOMAIN_IN_REFERENCES 0.000000, __MULTIPLE_RCPTS_CC_X2 0.000000, __NO_HTML_TAG_RAW 0.000000, __OUTBOUND_SOPHOS_FUR 0.000000, __OUTBOUND_SOPHOS_FUR_IP 0.000000, __OUTBOUND_SOPHOS_FUR_RDNS 0.000000, __PASSWORD_IN_BODY 0.000000, __PHISH_SPEAR_SUBJ_PREDICATE 0.000000, __RCVD_CTE 0.000000, __RCVD_EXIM_4_96_AES_128 0.000000, __RCVD_FROM_HOMEUSER 0.000000, __REFERENCES 0.000000, __SANE_MSGID 0.000000, __SL_HEAVY 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_STARTS_S_BRACKETS 0.000000, __TO_MALFORMED_2 0.000000, __TO_NO_NAME 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000 Content-Type: text/plain; charset="utf-8" hci_le_conn_failed() unconditionally calls hci_enable_advertising(), although its own comment states advertising should be re-enabled only when the failed attempt was made as a peripheral. hci_le_conn_failed() is reached from hci_conn_failed() for every failed LE connection, including outgoing central connections. For a central attempt this enable is redundant: hci_le_create_conn_sync() already restores advertising via hci_resume_advertising_sync() in its done: block. Because hci_enable_advertising() only queues the work on cmd_sync_work, it runs *after* that resume has already succeeded and set HCI_LE_ADV. The resulting HCI sequence, captured on a BCM43455 (no LE Extended Advertising, so legacy advertising is used): LE Create Connection Status Success ... 13.8 s, peer never answers ... LE Set Advertising Parameters (0x2006) Success <- done: resume, LE Set Advertising Enable (0x200a) Success HCI_LE_ADV set LE Create Connection Cancel (0x200e) Success LE Connection Complete Unknown Conn Id LE Set Advertising Parameters (0x2006) Command Disallowed (0x0c) The last command is the queued enable from hci_le_conn_failed() running as a second hci_enable_advertising_sync() pass. It clears HCI_LE_ADV (hci_sync.c, "Clear the HCI_LE_ADV bit temporarily"), then sends LE Set Advertising Parameters while the controller is still advertising, which the controller correctly rejects with Command Disallowed. The disable-first call at the top of hci_enable_advertising_sync() cannot prevent this: hci_disable_advertising_sync() returns early without sending anything when HCI_LE_ADV is clear, so it is a no-op exactly when the flag is wrong. hci_enable_advertising_sync() then returns without sending LE Set Advertising Enable, so HCI_LE_ADV is never set again. The legacy software rotation loop re-arms hci_schedule_adv_instance_sync() every HCI_DEFAULT_ADV_DURATION (2 s), and its "already advertising" shortcut tests HCI_LE_ADV, which can no longer become true. The command is therefore retried every 2 s indefinitely: Bluetooth: hci0: Opcode 0x2006 failed: -16 Observed on a gateway as 5326 occurrences over 3 hours, ending only when bluetoothd was restarted. Connection attempts that succeed do not call hci_le_conn_failed() and never trigger this. Add the role test the comment already describes. Both other hci_enable_advertising() call sites reached from a failed/closed LE connection (hci_cs_disconnect() and hci_disconn_complete_evt()) already guard on conn->role =3D=3D HCI_ROLE_SLAVE; this one was missed. Reproducing needs legacy advertising (ext_adv_capable() false, so the software rotation loop is used), simultaneous peripheral advertising and outgoing central connects, and a central connect that times out rather than failing fast. The Fixes tag points at the commit that introduced the advertising restart into this path for the directed-advertising (peripheral) case; the role test that the later commit 0b1db38ca26b ("Bluetooth: Fix check for direct advertising") added to the sibling paths was never applied here. Fixes: 3c857757ef6e ("Bluetooth: Add directed advertising support through c= onnect()") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 btmon Signed-off-by: Valentin Kindschi --- Changes in v2: - Rebased onto bluetooth-next; no functional change. net/bluetooth/hci_conn.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c --- a/net/bluetooth/hci_conn.c +++ b/net/bluetooth/hci_conn.c @@ -1262,7 +1262,8 @@ static void hci_le_conn_failed(struct hci_conn *conn,= u8 status) /* Enable advertising in case this was a failed connection * attempt as a peripheral. */ - hci_enable_advertising(hdev); + if (conn->role =3D=3D HCI_ROLE_SLAVE) + hci_enable_advertising(hdev); } /* This function requires the caller holds hdev->lock */ -- 2.34.1 From nobody Mon Sep 28 21:03:43 2026 Received: from remote.fiveco.ch (remote.fiveco.ch [46.14.118.250]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6891142587A for ; Mon, 17 Aug 2026 13:25:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=46.14.118.250 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786973124; cv=none; b=O4roUufTR+vu5UR8mCZfFf+2axQGLaOSyaJIKVj4ZDbdLsymkX+1C+vhH3YoCOa3WpM1vKUhns1fFcM6ezPdSP89a9YBzRChPoafqG/xgMGvc7Vs8PmOxORwsuRD2IzUbTHMpHefEd4bkQs0f8PYlcxIuFRl7qePJFicZRqKtcQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786973124; c=relaxed/simple; bh=AHH0xAl5IsP5wi0pch4r5ROqMhCdjRnuKYmMHXFXcjo=; h=Content-Type:From:To:CC:Subject:Date:Message-ID:In-Reply-To: References:MIME-Version; b=K2JNBxIvo1Ts27ykrhgyO+hVi5EXoDDmU4oFlY4AOZKkn6e6snyOxENPH+qcaI99oCvE4obGOnOskTGLdipOKqE2/sSYSOd8h2naWsXz+IsEI7hglNXOgxYeYDO8qU47HG5SL5cgk8SnYLkDN5k4MSMknUSWKqm9iLgYdYegNbo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=fiveco.ch; spf=pass smtp.mailfrom=fiveco.ch; dkim=pass (1024-bit key) header.d=fiveco.ch header.i=@fiveco.ch header.b=YnkvBoFh; arc=none smtp.client-ip=46.14.118.250 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=fiveco.ch Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=fiveco.ch Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=fiveco.ch header.i=@fiveco.ch header.b="YnkvBoFh" Received: from [192.168.16.44] (port=25384 helo=remote.fiveco.ch) by remote.fiveco.ch with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1wvxKv-000000001bg-0Kpu; Mon, 17 Aug 2026 15:25:09 +0200 Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; d=fiveco.ch; s=fiveco; c=simple/simple; t=1786973109; h=from:subject:to:date:message-id; bh=AHH0xAl5IsP5wi0pch4r5ROqMhCdjRnuKYmMHXFXcjo=; b=YnkvBoFh7vvywBePKxsUQlDu5QELfIMG/C89zV8j94NIiAWrSOZESHp94xY/MDESq4bkMuf1XPV Kbf1GnP4WEUGI6xadhc6lBap+kkTiJpNiMlF70INDoIG1LXx2AuJ6OczDchMZaYeSkP7Tqh352z0B SwN6bSt0LjQAF5KcPbU= Received: from fiveco-vm-vk1.fiveco.local (192.168.16.29) by FIVECO-MX01.fiveco.local (192.168.16.44) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.61; Mon, 17 Aug 2026 15:25:08 +0200 From: Valentin Kindschi To: CC: , , , , Valentin Kindschi , Subject: [PATCH v2 2/2] Bluetooth: hci_event: keep HCI_LE_ADV set when the host cancelled the connection Date: Mon, 17 Aug 2026 15:24:49 +0200 Message-ID: <20260817132449.509304-3-valentin.kindschi@fiveco.ch> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260817132449.509304-1-valentin.kindschi@fiveco.ch> References: <20260817132449.509304-1-valentin.kindschi@fiveco.ch> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-ClientProxiedBy: FIVECO-MX01.fiveco.local (192.168.16.44) To FIVECO-MX01.fiveco.local (192.168.16.44) X-Sophos-OBS: success X-SASI-Version: Antispam-Engine: 6.0.0.1, AntispamData: 2026.8.17.125719 X-SASI-RCODE: 200 X-SASI-SpamProbability: 10% X-SASI-Hits: ADVERT_CODE2 0.400000, BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, MULTIPLE_RCPTS 0.100000, NO_CTA_URI_FOUND 0.000000, NO_FUR_HEADER 0.000000, NO_URI_HTTPS 0.000000, OUTBOUND 0.000000, OUTBOUND_SOPHOS 0.000000, REFERENCES 0.000000, SENDER_NO_AUTH 0.000000, TRANSACTIONAL 0.000000, WEBMAIL_SOURCE 0.000000, WEBMAIL_XOIP 0.000000, WEBMAIL_X_IP_HDR 0.000000, __ADVERT_CODE2 0.000000, __ANY_URI 0.000000, __B2B_PROBE 0.000000, __BODY_NO_MAILTO 0.000000, __BULK_NEGATE 0.000000, __CC_NAME 0.000000, __CC_NAME_DIFF_FROM_ACC 0.000000, __CC_REAL_NAMES 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FRAUD_MONEY_DENOMINATION 0.000000, __FUR_RDNS_SOPHOS 0.000000, __HAS_CC_HDR 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_XOIP 0.000000, __HAS_X_MAILER 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MSGID_DOMAIN_IN_REFERENCES 0.000000, __MULTIPLE_RCPTS_CC_X2 0.000000, __NO_HTML_TAG_RAW 0.000000, __OUTBOUND_SOPHOS_FUR 0.000000, __OUTBOUND_SOPHOS_FUR_IP 0.000000, __OUTBOUND_SOPHOS_FUR_RDNS 0.000000, __RCVD_CTE 0.000000, __RCVD_EXIM_4_96_AES_128 0.000000, __RCVD_FROM_HOMEUSER 0.000000, __REFERENCES 0.000000, __SANE_MSGID 0.000000, __SL_HEAVY 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_STARTS_S_BRACKETS 0.000000, __SUBJ_TRANSACTIONAL 0.000000, __SUBJ_TR_GEN 0.000000, __TO_MALFORMED_2 0.000000, __TO_NO_NAME 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000 Content-Type: text/plain; charset="utf-8" le_conn_complete_evt() clears HCI_LE_ADV before looking at the event status: /* All controllers implicitly stop advertising in the event of a * connection, so ensure that the state bit is cleared. */ hci_dev_clear_flag(hdev, HCI_LE_ADV); The premise fails for Unknown Connection Identifier (0x02), which is what an HCI_LE_Connection_Complete carries after the host issued LE Create Connection Cancel: no connection was created and the controller never stopped advertising. Clearing the flag there makes the host believe advertising is off while the controller has it on. Other non-zero statuses must keep clearing it. Advertising Timeout (0x3c) in particular means the controller gave up advertising on its own, so the flag has to go; leaving it set would make the "already advertising" shortcut in hci_schedule_adv_instance_sync() skip the HCI commands and silently stop advertising altogether. With legacy advertising the disagreement is self-sustaining. On the next software rotation tick hci_enable_advertising_sync() runs: - hci_disable_advertising_sync() returns early without sending anything, because HCI_LE_ADV is clear; - LE Set Advertising Parameters is then sent while the controller is still advertising, and is correctly rejected with Command Disallowed (0x0c); - the function returns before LE Set Advertising Enable, so nothing re-sets HCI_LE_ADV. hci_schedule_adv_instance_sync() re-arms adv_instance_expire every HCI_DEFAULT_ADV_DURATION (2 s) and its "already advertising" shortcut tests HCI_LE_ADV, which can no longer become true, so the command is retried every 2 s indefinitely: Bluetooth: hci0: Opcode 0x2006 failed: -16 Captured on a BCM43455 (no LE Extended Advertising) after a central connection attempt timed out and was cancelled: LE Set Advertising Parameters (0x2006) Success LE Set Advertising Enable (0x200a) Success HCI_LE_ADV set LE Create Connection Cancel (0x200e) Success LE Connection Complete Unknown Conn Id <- flag cleared LE Set Advertising Parameters (0x2006) Command Disallowed [+2.033 s] LE Set Advertising Parameters (0x2006) Command Disallowed [+2.016 s] ... Keep the flag only for the host-cancelled case. Fixes: fbd96c151cdc ("Bluetooth: Fix clearing HCI_LE_ADV for LE connections= ") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 btmon Signed-off-by: Valentin Kindschi --- Changes in v2: - Rebased onto bluetooth-next; no functional change. v1's hci_event.c context lacked the hci_store_wake_reason() call present in mainline, so the hunk did not apply. net/bluetooth/hci_event.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c --- a/net/bluetooth/hci_event.c +++ b/net/bluetooth/hci_event.c @@ -5720,10 +5720,12 @@ static void le_conn_complete_evt(struct hci_dev *hd= ev, u8 status, hci_dev_lock(hdev); hci_store_wake_reason(hdev, bdaddr, bdaddr_type); =20 - /* All controllers implicitly stop advertising in the event of a - * connection, so ensure that the state bit is cleared. + /* Advertising stops when a connection is created, and when the + * controller gives up advertising on its own. It keeps advertising + * when the host cancelled an outgoing connection. */ - hci_dev_clear_flag(hdev, HCI_LE_ADV); + if (status !=3D HCI_ERROR_UNKNOWN_CONN_ID) + hci_dev_clear_flag(hdev, HCI_LE_ADV); =20 /* Check for existing connection: * -- 2.34.1